Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
HIGH 8.2 CVE-2026-73350 Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-68568 Subscriber Privilege Escalation in MasterStudy LMS <= 3.7.41 versions. Fix unknown Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-28191 Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions. Fix unknown Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2024-14045 A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse… Fix unknown Fix from $4,0002026-08-18 HIGH 7.9 CVE-2026-15218 A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide perm… Fix unknown Fix from $4,9002026-08-17 MEDIUM 5.4 CVE-2026-19986 A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the… Fix unknown Fix from $4,0002026-08-17 MEDIUM 6.3 CVE-2026-19928 A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/R… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19918 A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag… No fix yet Fix from $4,0002026-08-16 CRITICAL 9.8 CVE-2026-72826 The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in … No fix yet Fix from $5,7502026-08-14 CRITICAL 9.8 CVE-2026-72839 filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthen… No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-72840 OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended … No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation No fix yet Fix from $4,0002026-08-13 HIGH 7.7 CVE-2026-66661 Subscriber Privilege Escalation in Directories Pro <= 2.0.5 versions. No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-66424 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-61979 Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-28161 Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-27543 Unauthenticated Privilege Escalation in MStore API <= 4.20.0 versions. No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-64639 Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute … No fix yet Fix from $5,7502026-08-12 MEDIUM 5.3 CVE-2026-71468 A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token … No fix yet Fix from $4,0002026-08-11 HIGH 7.6 CVE-2026-18621 A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a maliciou… No fix yet Fix from $4,9002026-08-10 HIGH 8.1 CVE-2026-15467 A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by … No fix yet Fix from $4,9002026-08-10 HIGH 7.8 CVE-2026-19381 A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library N… No fix yet Fix from $4,9002026-08-10 HIGH 7.3 CVE-2026-19376 A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php… No fix yet Fix from $4,9002026-08-10 MEDIUM 6.3 CVE-2026-19358 A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation ca… No fix yet Fix from $4,0002026-08-09 HIGH 7.8 CVE-2026-19191 A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\S… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19192 A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19193 A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter … No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19195 A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the co… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19190 A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Se… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-19189 A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows… No fix yet Fix from $1,9502026-08-07